Ransom

Ransom:Win32/Dcryggon.A removal guide

Malware Removal

The Ransom:Win32/Dcryggon.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Dcryggon.A virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.

Related domains:

s7c4wrcmzgbtldbs.hiddenservice.net

How to determine Ransom:Win32/Dcryggon.A?


File Info:

crc32: 6BFCFA23
md5: 756571c6b13c998c8b0957782452027e
name: 756571C6B13C998C8B0957782452027E.mlw
sha1: 671f8f06f97bfc393d1e6a18a4a662fd82505a7f
sha256: 0d7879288486271da132fb8811da9c6aa07ad407247c4c7747b7a79873889c69
sha512: 129d7443608c5c4ae38293dda7ae48a1fc06dfcce084a6c823317fceb40e9ac4372deb9a59bdf524a9f28ed4c4872f807c976b0fbee3d1fe43f22c4c78621c8b
ssdeep: 12288:PM0TBg9rBlclNSsSeUXWkU3iTzcTgqvc1sQt/skMADErukZWhxyc:PM0orBOvSw/UoUqv0hOrXayc
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Ransom:Win32/Dcryggon.A also known as:

K7AntiVirusTrojan ( 00512f551 )
LionicTrojan.Win32.Purgen.4!c
DrWebTrojan.Encoder.12950
CynetMalicious (score: 100)
ALYacGenPack:Generic.Ransom.Spora.091410BC
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.15498
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Purgen.ab5b2cc7
K7GWTrojan ( 00512f551 )
Cybereasonmalicious.6b13c9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NMZ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Purgen.fz
BitDefenderGenPack:Generic.Ransom.Spora.091410BC
NANO-AntivirusTrojan.Win32.Purgen.fnmrgn
MicroWorld-eScanGenPack:Generic.Ransom.Spora.091410BC
TencentWin32.Trojan.Purgen.Aguv
Ad-AwareGenPack:Generic.Ransom.Spora.091410BC
SophosMal/Generic-S
ComodoMalware@#3lgbw5rleue64
BitDefenderThetaAI:Packer.A1EB297719
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.756571c6b13c998c
EmsisoftGenPack:Generic.Ransom.Spora.091410BC (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1119328
MicrosoftRansom:Win32/Dcryggon.A
ArcabitGenPack:Generic.Ransom.Spora.D16512BC
GDataGenPack:Generic.Ransom.Spora.091410BC
McAfeeArtemis!756571C6B13C
MAXmalware (ai score=87)
VBA32TrojanRansom.Purgen
PandaTrj/CI.A
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.11186641.susgen
FortinetW32/Filecoder.NMZ!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom:Win32/Dcryggon.A?

Ransom:Win32/Dcryggon.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment